Live data from Hacker News

PAM Duress – Alternate passwords for panic situations

github.com

271–280 of 358 posts

Re: PAM Duress – Alternate passwords for panic situations

#272
post #174
post #146

Earlier quoted context omitted.

Time to post this again: https://www.youtube.com/watch?v=d-7o9xYp7eE (Don't talk to the police)

Everytime this is posted I feel the need to mention to Brits specifically: this does not apply. "It may harm your defence if when questioned you fail to mention something you will later rely on in court". Failure to answer can seriously harm your defence and I've heard of people I personally know (though I wasn't in the courtroom) where the prosecution hammered the point that they "came up with a plausible sounding s…

The right to silence began in England and it's only because of the endless undercutting of rights going on there and the lack of backbone for standing up to this (liberalism is now seemingly a historical footnote for the UK) that it has caveats, the right to silence has still not disappeared entirely.

As even the Wikipedia article on it[1] notes:

> If this failure occurs at an authorised place of detention (e.g. a police station), no inferences can be drawn from any failure occurring before the accused is allowed an opportunity to consult a legal advisor.

The "Don't talk to the police" is not the full point made in that video, it's "Don't talk to the police… until you've spoken to your legal advisor and not without a legal advisor present".

So, *don't talk to the police*, they're not your friends and they don't have your best interests at heart and it's their job to get evidence against you, not yours.

[1] https://en.wikipedia.org/wiki/Right_to_silence_in_England_an...

Re: PAM Duress – Alternate passwords for panic situations

#273
post #106

Earlier quoted context omitted.

I don't know the legal implications, but if the duress password unlocks your device and simply deletes a directory or two, and the officer only asked you to unlock your device (without a warrant, by the way), how is that lying?

Even if it isn't lying, it's destruction of evidence. 18 U.S. Code 1519: > Whoever knowingly alters, destroys, mutilates, conceals, covers up, falsifies, or makes a false entry in any record, document, or tangible object with the intent to impede, obstruct, or influence the investigation or proper administration of any matter within the jurisdiction of any department or agency of the United States or any case filed u…

If they can prove it, you're in trouble. How are they going to prove it?

Re: PAM Duress – Alternate passwords for panic situations

#274

I hate when my bank calls me about something and then asks to confirm my identity prior to giving out details about my account. Even when I think I know what it is about (e.g., a transaction with my card was declined just before the phone call), I feel very strange giving out any information to an inbound caller. One thing I have thought about doing is providing mistaken information to the caller and see if they go a…

Out here in developed-land I get a link mid-call via SMS, which I can confirm with the CS rep on the phone.

I click the link and authenticate with my bank credentials or mobile auth certificate.

The CS rep gets my info, which is authenticated to be correct and we get on with our day.

Re: PAM Duress – Alternate passwords for panic situations

#275

Earlier quoted context omitted.

Tell them you feel uneasy giving out details over the phone to an inbound caller, hang up and call their service line directly. The only way you can be sure you are talking to your bank is if you are calling them.

Wait a couple of minutes or call back from a different phone. In the UK it may still be possible for an attacker to hold the line open after you hang up - and then simulate the dial tone.

How? If I explicitly push the red button on my mobile phone, how does the line still stay open?

I can understand this attack via land line, but who seriously has a land line in 2021? Even my 93 year old grandma has a mobile phone. (Albeit we did get her one that looks like a land line phone :D )

Re: PAM Duress – Alternate passwords for panic situations

#276

Earlier quoted context omitted.

>imprison an innocent person. Kind a hard word to use for an arrest. In many places police can arrest you for some period if they suspect you have committed a crime. This is no different. No need for sensational language.

In the US they can’t do anything unless they have “probable cause” you committed a crime. That’s broad, but it excludes “this guy pushed the number 6 three times in a row.” And “imprison” and “arrest” are pretty darn close. In the US, when you are arrested, you are usually searched, fingerprinted, and a mugshot is taken. The mugshot can become a public record. There are websites that match mugshots to names, and make…

Probable cause isn't "pushed button multiple times" it is "silent alarm was triggered and this guy is on the only guy in the building".

If US is doing stupid shit then US is doing stupid shit. What else can we expect a third world country to do? In civilized world you are processed yes, but since you are just arrested and not accused you will just be held until the pre-investigation has concluded

Re: PAM Duress – Alternate passwords for panic situations

#277

I hate when my bank calls me about something and then asks to confirm my identity prior to giving out details about my account. Even when I think I know what it is about (e.g., a transaction with my card was declined just before the phone call), I feel very strange giving out any information to an inbound caller. One thing I have thought about doing is providing mistaken information to the caller and see if they go a…

Most banks here (UK) have a mobile app, so I've always wondered why they don't use that to auth the call? Bank: Hey I'm calling from HSBC, want to verify it? Me: Sure Bank: Ok, so open you mobile app, and enter 637482 Me: Ok, cool thats given me 274893 Bank: Yep, that's all confirmed so ...

I feel like training users to input codes into their banking app could lead to other less safe practices.

Re: PAM Duress – Alternate passwords for panic situations

#278
post #73

Earlier quoted context omitted.

I think on Android you can set up multiple users.

I'd love that feature (android 9+) if it allowed me to install some of the gazillion apps (e.g. every bloody fast food place that only has deals via their app) but restricts them from accessing my real user contacts, emails, msgs, gps/location, etc. Blackberry phones had this feature and it was pretty bulletproof.

Have a look at Shelter[1] or Insular[2]. Both make use of Android's work profile feature to completely isolate apps in a separate environment.

[1] https://f-droid.org/en/packages/net.typeblog.shelter

[2] https://f-droid.org/en/packages/com.oasisfeng.island.fdroid

Re: PAM Duress – Alternate passwords for panic situations

#279

Earlier quoted context omitted.

Out of interest, were you arrested? As part of a duress protocol — where your extortioner is likely observing you — law enforcement would be required to go through the motions of arresting you and taking you offsite. You can expect to be held for X hours regardless of whether they believed you had simply made a mistake. Long and unavoidable administrative delays make it much harder for villains to subvert protocols.…

No arrests. False alarms on silent alarm systems are common. Other factors made it clear that a real threat was unlikely. All orgs should consider locking out all employees for at least one uninterrupted week a year. Very easy way to shake out all sorts of problems.

> All orgs should consider locking out all employees for at least one uninterrupted week a year. Very easy way to shake out all sorts of problems.

Could you give some examples?

Post reply on HN